Risk management
Risks you can follow. From the first assessment to the next review.
Trustbird keeps one risk register for every standard you carry. Each risk is linked to the systems, processes and suppliers it affects and to the controls that treat it, so you can always see why a risk exists and what you are doing about it.
- Every risk linked to what it affects
- Risk acceptance by a named person
- Periodic review with reminders
A register that reflects how your organization works
A risk register is useful when it starts from real things: the systems you run, the data you hold and the suppliers you depend on. Trustbird builds the register on that picture of your organization.
One risk register
Record risks once and use them for ISO 27001, NEN 7510 and ISO 9001. No separate lists per standard.
Linked to your organization
Link each risk to the assets, processes and suppliers it concerns. When something changes there, you see which risks need another look.
Likelihood and impact
Assess each risk on likelihood and impact with a method you define. The outcome shows which risks need attention first.
Treatment plans
Decide how to treat each risk, link the controls that reduce it and assign actions with an owner and a due date.
Acceptance by a named person
A remaining risk is accepted only by the person you designate. The decision is recorded with name, date and reasoning.
Periodic review
Set how often each risk is reviewed. Owners get a reminder in time, and every earlier assessment remains visible in the history.
How it works
-
01
Describe what matters
Answer plain questions about your systems, data, processes and suppliers. Trustbird uses the answers as the basis for the register.
-
02
Identify and assess
Record the risks that apply to you and assess likelihood and impact. Ask yourself questions like: what happens if this supplier is unavailable for a week?
-
03
Decide on treatment
Link controls, plan actions and have the designated person accept what remains.
-
04
Review on schedule
Trustbird reminds owners when a review is due and keeps the full history for the auditor.
Frequently asked questions
- Can I use my own risk assessment method?
- Yes. You define the scales for likelihood and impact and what level of risk is acceptable to you. Trustbird applies that method consistently across the register.
- Can the AI accept a risk?
- No. The AI can suggest risks and point out inconsistencies, but only a named person in your organization can accept or close a risk.
- Do I need a separate risk register per standard?
- No. One register serves every standard you carry. Where a standard asks for something specific, Trustbird shows it as an addition to the same register.
Related
- Policy and documents Versioned policy with a named owner
- Controls and evidence Supply evidence once, use it everywhere
- Internal audit and management review Audits and reviews from your own data
- Supplier management Know who processes which data
- Trustbird AI An assistant that proposes, not decides
- Trust center Show customers how you work securely
See what Trustbird does for your organization
Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing. Apply as a design partner, or mail us with a question.